Server Cookie Vulnerability in NLnet Labs Unbound Product Line
CVE-2026-54478

3.7LOW

Key Information:

Vendor

Nlnet Labs

Status
Vendor
CVE Published:
22 July 2026

What is CVE-2026-54478?

A vulnerability exists in NLnet Labs Unbound versions 1.18.0 to 1.25.1, where the server-cookie SipHash is computed over the proxy's wire address rather than the intended client. This flaw allows an off-path attacker to potentially harvest a valid server cookie from a single legitimate query and reuse it to bypass DNS Cookie checks, compromising the integrity and security of DNS responses. This vulnerability highlights significant risks in environments employing PROXYv2, necessitating prompt remediation.

Affected Version(s)

Unbound 1.18.0 < 1.25.2

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Qifan Zhang (Palo Alto Networks)
.